Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Microsoft Copilot CoSnitch Flaw Lets Attackers Steal Sensitive Data
August 19, 2026
Cl0p Hackers Exploit Critical PTC Windchill CVE-2023-XXXX to Steal Data
August 19, 2026
Irregular Boosts AI Security with Stronger Containment Standards
August 19, 2026
Home/Threats/Speagle Malware Hijacks Cobra DocGuard to Steal Data
Threats

Speagle Malware Hijacks Cobra DocGuard to Steal Data

Key Takeaways A new information-stealing malware, Speagle, has been identified, specifically targeting organizations using EsafeNet’s Cobra DocGuard platform. Speagle is designed to exfiltrate...

David kimber
David kimber
March 20, 2026 4 Min Read
84 0

Key Takeaways

  • A new information-stealing malware, Speagle, has been identified, specifically targeting organizations using EsafeNet’s Cobra DocGuard platform.
  • Speagle is designed to exfiltrate highly sensitive data, including documents related to Chinese ballistic missile technology, by masquerading as legitimate software.
  • The threat actor, dubbed Runningcrab, is highly sophisticated, leveraging compromised Cobra DocGuard servers for command-and-control and using the platform’s own drivers for self-deletion.
  • The infection vector is suspected to be a supply chain attack, highlighting the critical need for robust software supply chain security.

A sophisticated new infostealer malware, dubbed Speagle, is actively compromising organizations that rely on Cobra DocGuard, a document security and encryption platform developed by Chinese firm EsafeNet. This threat, detailed in a recent analysis, is engineered to blend seamlessly into its target environment, leveraging the very software it aims to exploit as a cover for its covert data exfiltration operations. Speagle’s capabilities extend beyond generic system information theft, specifically seeking out and stealing files related to highly sensitive topics, including documents concerning Chinese ballistic missiles.

Table Of Content

  • Key Takeaways
  • How Speagle Collects and Exfiltrates Stolen Data
  • Phase 1: Initial Reconnaissance
  • Phase 2: System and Network Mapping
  • Phase 3: Browser Data Exfiltration
  • What You Should Do

Cobra DocGuard has a documented history of security vulnerabilities and exploitation. In September 2022, the platform was implicated in a supply chain attack that targeted a gambling enterprise in Hong Kong. Later, in August 2023, the threat group known as Carderbee exploited Cobra DocGuard to deploy the Korplug backdoor, also identified as PlugX, against various organizations across Hong Kong and other parts of Asia. This recurring pattern underscores Cobra DocGuard’s consistent appeal to attackers who view it as a trusted, widely deployed entry point into victim networks.

Analysts at Symantec identified Speagle as a 32-bit .NET executable that only fully activates its malicious payload on systems where Cobra DocGuard is present. The actor behind this campaign has been designated Runningcrab, although no definitive links to any previously known threat groups have been established. Researchers postulate that the actor is likely either state-sponsored or a highly skilled private contractor, a conclusion drawn from the malware’s precise targeting of Cobra DocGuard users and its specific focus on defense-related documentation.

While the exact infection vector remains unconfirmed, initial evidence points towards a possible supply chain attack. Speagle employs a legitimate Cobra DocGuard driver, specifically the FileLock driver, to remove itself from the compromised system once its operations are complete. This behavior is consistent with Trojanized software updates. The self-deletion mechanism utilizes the SetFileInformationByHandle() API to rename and then delete the running executable, a technique previously discovered by security researcher Jonas Lykkegaard. The use of the platform’s own driver for self-removal strongly suggests that the attacker possesses intimate knowledge of Cobra DocGuard’s internal architecture.

Further demonstrating its sophistication, Runningcrab has been observed hijacking a legitimate Cobra DocGuard server belonging to the targeted organization. This compromised server then served as the command-and-control (C2) infrastructure for the malware. By routing exfiltrated data through a server that the victim organization regularly communicates with, the attacker effectively camouflaged the malicious traffic, making it appear entirely normal. This level of meticulous planning indicates a well-resourced actor with prior reconnaissance and understanding of the victim’s network environment.

How Speagle Collects and Exfiltrates Stolen Data

Upon verifying the installation of Cobra DocGuard through specific Windows registry keys under the Esafenet CDG System path, Speagle initiates a methodical, multi-stage data collection process.

Phase 1: Initial Reconnaissance

The first phase involves gathering fundamental system information, including the machine’s username, hostname, and unique Cobra DocGuard client identifiers found in local configuration files. Should the malware fail to locate a valid client ID, it immediately triggers its self-deletion routine and terminates without attempting any data theft.

Phase 2: System and Network Mapping

In the second phase, Speagle executes Windows Management Instrumentation (WMI) queries to collect detailed information about active processes, network connections, installed services, scheduled tasks, and firewall rules. Concurrently, it maps files and folders across all connected drives, constructing a comprehensive overview of the compromised machine’s contents.

Phase 3: Browser Data Exfiltration

The third phase targets sensitive browser data. Speagle extracts browsing history, autofill entries, downloaded files, bookmarks, and search shortcuts from directories associated with Chromium-based browsers.

One identified variant of Speagle possesses enhanced capabilities, specifically scanning for documents containing Chinese-language keywords related to defense technology. These keywords translate to terms such as “ballistic missile,” “hypersonic,” “warhead,” “Dongfeng,” and “Changjian,” directly referencing specific Chinese missile systems, including the Dongfeng-27.

One version of Speagle searches for files related to Chinese ballistic missiles (Source - Symantec)
One version of Speagle searches for files related to Chinese ballistic missiles (Source – Symantec)

After each data collection phase, Speagle compresses the gathered information using the Deflate algorithm, encrypts it with AES-128 in CBC mode, and then transmits it via HTTP POST requests to a hardcoded, compromised Cobra DocGuard server.

What You Should Do

  • Immediately audit outbound network traffic for any unexpected connections to the IP addresses 60.30.147[.]18 and 222.222.254[.]165.
  • Update endpoint detection and response (EDR) tools to identify and flag Speagle’s four known SHA-256 file hashes.
  • Verify the integrity of all Cobra DocGuard server installations within your environment.
  • Scrutinize software update channels for Cobra DocGuard for any signs of unauthorized modifications or suspicious activity.
  • Apply the latest endpoint protection signatures and ensure all security software is up-to-date.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Apex AI Pentesting Tool Finds App Vulnerabilities in Black-Box Mode

Next Post

Critical Atlassian Bamboo RCE Vulnerability CVE-2024-1597 Patched

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical MLflow SSRF vulnerability CVE-2023-XXXX exploited in the wild
August 18, 2026
French Tax Authority Data Breach Exposes Over 600,000 Users’ Personal Tax Data
August 18, 2026
Microsoft 365 Search Outage Disrupts SharePoint, OneDrive, Outlook Globally
August 18, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us